Security

Work that stays in your hands.

Thirdpen acts in your apps, so it is built to ask before it acts, keep each piece of work apart, and remember only what it should.

Send Dana the follow-up.

Here’s the draft. It goes out once you allow it.

Sales wants to send email in Gmail

This runs in your connected Gmail account. Nothing happens until you allow it.

Send email · Gmail
Recipient email
dana@northwind.co
Subject
Following up on Tuesday
Body
Hi Dana, congrats on the Reno opening. Here’s how the first month would look.

01 · Approvals

Nothing leaves without your Allow.

Thirdpen works in your apps, so it treats every change to the outside world as yours to approve.

  • A card before every send

    Before it sends, posts, shares, invites, pays or deletes anything in a connected app, Thirdpen stops and shows you exactly what it will do. It runs only when you press Allow.

  • Four permission modes

    Read only, Ask, Auto, Auto-all. Reading and working in its own computer never need a card; changes to your apps follow the mode you choose.

  • Switches for each app

    For every connected app you decide whether agents may make changes, and separately whether they may delete.

  • When in doubt, it asks

    An action Thirdpen cannot classify is treated as a change. The worst case is one card too many, never an action you did not see.

  • Your reply cancels the card

    If you answer in the chat instead of pressing Allow, the waiting action is cancelled and never runs.

  • Routines have guardrails

    A routine runs with nobody watching, so the tools that create or change agents, skills and apps are switched off for scheduled runs.

02 · Isolation

Every piece of work on its own computer.

Code, files and the browser for a thread run in a sandbox of their own, apart from every other thread.

  • A private machine per thread

    Each thread gets its own sandboxed Linux container with its own browser. Nothing one thread runs can reach another.

  • You sign in, not the agent

    When a site needs a password, a passkey, a CAPTCHA or a payment, the agent pauses and hands the browser to you.

  • No open ports

    The browser’s control port is never exposed to the internet. The live view reaches you only through your signed-in session.

  • Uploads never run

    Files you upload are always served as downloads and previewed in a sandbox, so a file can never run as a page on thirdpen.app.

03 · Privacy

It remembers only what it should.

Memory makes the next piece of work easier. It is kept narrow on purpose.

  • Incognito threads

    Only their creator can open them. They never appear in anyone’s list and are never written to memory.

  • Memory kept apart

    What Thirdpen learns about you is stored separately from what each agent knows about its work, and the two are never searched together.

  • Shared on purpose

    Other threads are visible to everyone in your workspace, so the team can pick up the work. Pins stay personal.

04 · Access

Accounts and roles.

Who can change the workspace is decided by role, and checked on every request.

  • Admins run the workspace

    Workspace admins manage members, connected apps and the team’s skills. Only an app’s creator or an admin can delete it.

  • Signed sessions

    Sessions use signed cookies, and requests from another site that try to change data are rejected.

  • Short-lived reset links

    Password reset links expire after an hour.

05 · Providers

Who we work with.

The services that process data to run Thirdpen, and what each one is for.

ProviderUsed for
CloudflareHosting, database, file storage, sandboxed computers and email
GoogleGemini, the AI models that do the work
ComposioConnections to your work apps
SupermemoryLong-term memory
Parallel and ExaWeb search
OwostackUsage metering

06 · Report an issue

Found a problem? Tell us first.

Email yaqeen@thirdpen.app with what you found and the steps to reproduce it. We will reply and keep you updated while we fix it.

Please give us a reasonable chance to fix it before you share it, and don’t access or change other people’s data while you test.